The Growing Size of Media: Just How Much Information Can Be Stored on 1TB?

November 3, 2020 at 9:00 am by Amanda Canale

When it comes to data storage, it’s difficult for many of us to fathom just how much information can fit on a portable hard drive or basic USB thumb drive. Many of us probably haven’t even filled up our own personal hard drives or come close to it. In the age of Big Data, USBs and portable hard drives have become the technological highways that bridge data between devices.

Now let’s think about how much information and data can be stored on a one terabyte (1TB) hard drive. For reference, a 1TB hard drive is equivalent to 1,000 gigabytes (GB). Maybe a couple thousand photos? A hundred movies or so? Well, the answer may shock you so let’s break it down by media type.


Photos
Depending on the file type and size, a 1TB hard drive can hold anywhere between 250,000 and 310,000 photos. Just imagine how many family photo albums you can fill with 250,000 photos. It’s incomprehensible! Some of you may be thinking, “what would a thief want with my personal photos?” While the data stored in personal photos may not be always be confidential, it’s still private and personally identifiable. This means that if a thief were to steal your 1TB drive filled with family photos, the risks of the breach can still be high as whatever information that is offered in the photographs is now fair game. The thief could find out about what kind of material possessions you own, such as cars, jewelry, and furniture, where you like to vacation, where you live, and what you look like, making future theft and targeting that much easier.

Photographs may seem low on the ladder as far as sensitive information, but they can offer up more information than you’re probably willing to give up. Take for instance last year’s U.S. Customs and Border Protection (CBP) data breach. In June 2019, the CBP released a statement that photographs and video recordings of fewer than 100,000 people and their vehicles were stolen as part of an attack on a federal subcontractor. The photographs and video recordings were used in a growing facial-recognition program to assist the CBP in tracking the identity of people entering and exiting the United States. The photographs and footage were originally taken at various American airports and land border crossings where vehicle license plates and faces were captured over a short period of time. While the thieves were not able to capture other identifying information such as passports or travel documents, this type of breach isn’t to be downplayed as the victims are now at major risk for identity theft.

Circuit board futuristic server code processing. Orange, green, blue technology background with bokeh. 3d rendering

Video and Audio
Home video enthusiasts can rejoice because storing all of your family videos in one place has become so much easier. A 1TB hard drive can hold up to 500 hours of high-definition 1080p video – that’s just over 20 full days! To put that into perspective, the total runtime of all the Marvel Cinematic Universe films (23 total) is approximately 50 hours – one-tenth the amount of storage.

Have a large music library? You’re in luck, too! A 1TB hard drive can hold up to 17,000 hours of audio files, totaling approximately 708 days’ worth. Still can’t fathom that much music? Imagine listening to the entire U2 studio album discography 24 times. Or listening to the entire Rolling Stones discography 15 times. Now that’s quite the road trip playlist!

data-security
Documents
Here comes the truly mind-boggling part. If we’re talking strictly Microsoft Word documents, a 1TB hard drive can hold (…wait for it…) 85 million documents. Take that in for a moment. Eighty-five million documents. A person’s entire life can fit onto a drive and still have plenty of room to spare. Bills, social security numbers, bank account information, deeds, birth certificates, and more can be stored on 1TB which makes them a gold mine for hackers and thieves.

Leslie Johnston, Chief of Repository Development for the Library of Congress, noted that a 1TB hard drive can hold as much information as one-tenth of the Library of Congress. Now that comparison makes our heads spin! It can be scary thinking about the irreparable damage hackers and thieves can cause with that much information at their fingertips.

In the United States, the average cost of a data breach can cause an organization to pay upwards of $8.9 million, averaging out approximately $146 to $250 per compromised record. Now imagine how much a breach of 85 million documents would cost. The risks of a data breach can be immeasurable, and the consequences are not always immediate. You can read more about how the purchase of in-house end-of-life data destruction equipment can save you and your organization millions of dollars here.

Clearly, a single 1TB hard drive can easily hold a lifetime’s worth of information (and then some), which is why having a secure end-of-life destruction plan is crucial in protecting that data. Protect yourself, your employees, and your company against future data breaches with one of our various high-quality NSA listed/CUI and unclassified magnetic media degaussers, IT crushers, and enterprise IT shredders. Any one of our exceptional sales team members are more than happy to help answer any questions you may have and help determine which machine will best meet your destruction needs.

Cost of a Data Breach vs. Hard Drive Crusher: How You Can Save Millions

October 6, 2020 at 8:15 am by Amanda Canale

In the age of Big Data, data breaches are, unfortunately, no longer a possibility of “if” but “when.” As we get deeper into the digital age, hackers and thieves no longer need to breach a facility’s physical barriers in order to steal your or your clients’ personally identifiable information (PII). They can access your confidential information through hacking the cloud, phishing company employees via email, and other more advanced virtual methods, with some resorting to the tried and true methods of dumpster diving or surfing eBay for hard drives.

From January to June 2019 there were more than 3,800 publicly disclosed data breaches that resulted in 4.1 billion records being compromised. That’s only within a six-month time window. While the rate of data breaches so far is slightly lower in 2020, there’s no real sign of it slowing down. For example, in July of this year, financial institution Morgan Stanley came under fire for an alleged data breach of their clients’ financial information after an ITAD (IT asset disposition) vendor misplaced various pieces of computer equipment storing customers’ personally identifiable information over a period of four years.

As we’ve stated in previous blogs, introducing third party data sanitization vendors into your end-of-life destruction procedure significantly increases the chain of custody, meaning that companies face a far higher risk of data breaches every step of the way. There have even been reports of some vendors selling end-of-life devices and their sensitive information to online third parties.

As the number of data breaches increase every year, so does the cost. According to the IBM and Ponemon Institute report, the cost of an average data breach in 2020 is $3.86 million, a 10% rise over the past five years. These costs range from money lost and reputation maintenance to regulatory fines and ransomware, among other direct and indirect costs. Depending on the company’s client demographic, state privacy lawyers may also need to be hired, which adds additional costs.

Settlement newspaper headline on money

The most expensive type of record is client PII and the least expensive type is employee PII, with healthcare taking the cake as the number one industry in terms of average cost of a data breach. In the U.S., organizations pay on average $8.9 million per data breach, averaging out to approximately $146.00 per compromised record. For reference, a one terabyte (1TB) hard drive can hold up to 310,000 photos, 500 hours of HD video, 1,700 hours of music, and upwards of 6.5 million document pages. Multiply those document pages by the average cost per record and you have a hefty, burning hole in your company’s pockets.

On average, 61% of data breach costs are within the first year, with 24% in the next 12-24 months, and the remaining 15% more than two years later.  It is because of this statistic that it is important to remember that there is no statute of limitations when it comes to data breaches. Companies with proper data security and end-of-life data destruction methods are likely to pay less in the case of a data breach but for those with little or no protection methods in place, the cost could be astronomical. Take for instance, British Airlines and Marriott: the two companies suffered data breaches in 2018 that cost them both upwards of $300 million.

According to the IBM report, it can take about 280 days for a company to identify and contain a data breach. Unfortunately, some companies may not be aware of these data breaches within that time, which can increase the cost of the prolonged breach. Marriott and Morgan Stanley had only discovered their data breaches after they had both been hacked over a four-year period. In cases like these, time really is money.

The consequences of improper data destruction are endless. It’s why we at SEM stress that companies handling confidential information opt for in-house end-of-life destruction as their sole destruction method. By purchasing an in-house IT crusher, such as our Model 0101 Automatic Hard Drive Crusher, companies have complete oversight and can be certain that their clients’ information has been securely destroyed. As we’ve learned, a reactionary approach is simply not enough.

Our Model 0101 has the capability to destroy all hard drives regardless of size, format, or type up to 1.85” high, which includes desktop, laptop, and server drives. With a simple push of a button, our crusher delivers 12,000 pounds of force via a conical punch that causes catastrophic damage to the drive and its internal platter, rendering it completely inoperable. That’s a lot of force. This model has a durability rating from the National Security Agency (NSA) of 204 drives per hour but has the ability to destroy up to 2,250 laptop drives per hour.

When comparing the cost of our Model 0101 at $5,066.88 (and an average lifespan of ten years) to a possible data breach resulting in millions of dollars, the right answer should be simple: by purchasing in-house end-of-life data destruction equipment, your company is making the most cost-effective, safest, and securest decision. Think of it as VERY inexpensive insurance!

At SEM we have an array of various high-quality NSA listed/CUI and unclassified magnetic media degaussers, IT crushers, and enterprise IT shredders to meet any regulation. Any one of our exceptional sales team members are more than happy to help answer any questions you may have and help determine which machine will best meet your destruction needs.

For more information on how maximizing every square foot of your facility with in-house data destruction is the best financial investment when it comes to proper data security, you can hear from Ben Figueroa, SEM’s Global Commercial Sales Director, below.

 

 

Security Engineered Machinery Destruction Devices Showcased in Google Data Center Security Video

September 21, 2020 at 5:17 pm by Amanda Canale

Security Engineered Machinery (SEM), global leader in high security end-of-life data destruction, was recently showcased in Google’s Data Center – Security Risk and Management video. The video, which was published to YouTube, showcases Google’s abundant commitment to data protection by virtually touring visitors through each step of the multi-layered security system.

The video details the six-layer security system the protects data within all Google data centers, ranging from smart fences and patrols that surround the edges of a data center property to the critical physical destruction of hard disk drives (HDDs) and solid state drives (SSDs) once they have reached the end of their useful life. Each additional measure adds a level of complexity and specificity, as even entering the building after initial security outside requires an extra identification check and an iris scan.

The sixth and final layer, which consists of erasing and physically destroying HDDs and SSDs, is showcased at the end of the video with SEM hard drive destruction equipment. Custom engineered to Google’s specifications, the devices shred high volumes of enterprise drives into tiny strips of metal, effectively destroying the platters of the drives, rendering them completely useless.

SEM hard drive destruction equipment can be seen in use in Google’s Data Center – Security Risk and Management video.

“SEM has always been about protecting information from those who wish us harm,” said Andrew Kelleher, CEO and President of SEM. “After 50 years of working with the US Government to protect classified information, it only makes sense for our business to extend to protect individual citizens’ information as well in areas like data centers that house private, sensitive information,” Kelleher added.

The physical destruction location is referred to as “the mysterious sixth layer” by Wong, the narrator of the video. The smallest number of building personnel are allowed in this data destruction room, where drives must be passed through a locker system to even reach the inside the room.

“We are honored to have our machines in use by one of tech’s greatest innovators,” commented Ben Figueroa, Strategic Account Manager at SEM. “We pride ourselves on having the most efficient, secure end-of-life solutions for sensitive data, and to be showcased in this video by one of the world’s largest data holders is a sign we are continuing to engineer our products with the future in mind.”

SEM additionally manufactures destruction devices that are capable of destroying paper, optical media, SSDs, and other electronic media devices for commercial and government clients around the world.

Debunking Hard Drive Destruction Misconceptions

September 9, 2020 at 2:18 pm by Amanda Canale

In October 2019, Blancco, an international data security company, released an article discussing various end-of-life data destruction methods and comparing drive destruction to data erasure. While we agree with some of what was written, we’d like to clear up a few things.

In the article, Blancco recommends weighing the level of impact certain end-of-life data can have in the case of a data breach combined with how quickly the data may age out. They then suggested basing the method of sanitization off of that assessment. We want to stress that there should never be an assessment of this nature when handling sensitive, confidential, or personally identifiable information (PII). It is always best practice to treat all end-of-life data as never aging out and having a potentially high level of harm if breached as both can be impossible to predetermine. Remember, there is no statute of limitations when it comes to data breach, meaning that an end-of-life drive can cause a breach years after it was discarded.

While some companies argue that drives should be reused as a more economical option, we disagree. By reusing devices, a company risks that leftover unencrypted or encrypted data getting into the wrong hands. Companies should future-proof their end-of-life data destruction procedures to ensure the prevention of future data breaches. This will not only save them time and money in the long run but prevents any damages to their customer base and reputation. (It’s better to be safe now than sorry in the long run!)

Blancco also notes that using a third-party vendor to sanitize and destroy end-of-life data and devices is an option. Morgan Stanley recently came under fire for the alleged data breach of their clients’ financial information after an ITAD (IT asset disposition) vendor misplaced a number of various computer equipment that were storing customers’ personally identifiable information (PII). Even though Blancco suggests carefully researching and vetting the vendors to ensure they are properly destroying your devices, introducing a third party significantly increases the chain of custody and companies face a far higher risk of data breach every step of the way when opting for this route.

While there are some reputable data sanitization vendors out there, it can be far too easy for ITAD vendors to misuse, mishandle, and misplace drives when in transportation, and in the actual acts of destruction and disposal. There have even been reports of some vendors selling end-of-life devices and their sensitive information to online third parties. We suggest getting rid of ITADs altogether if they’re part of your device destruction procedure simply because the security risks can be unpredictable and potentially catastrophic. Instead, we suggest purchasing one of our NSA listed devices, keeping the chain of custody within the company, and conducting all destruction in-house. You can read more of our thoughts on Morgan Stanley’s data breach here.

information-destruction

A common data destruction misconception is that erasing or overwriting a drive and degaussing are synonymous with one another. Unfortunately, that kind of thinking can quickly become dangerous depending on the kind of information you are looking to destroy. While methods such as cryptographic erasure and data erasure would allow the drive to be used again, as Blancco suggests, you run the high risk of leaving behind sensitive data which can become a gold mine for hackers and thieves.

While degaussing is not possible for the destruction of end-of-life data on solid state drives (SSDs), SEM always recommends following NSA standards and degaussing all magnetic media, including hard disk drives (HDDs), prior to destruction. Solid state drives (SSDs) and optical media do not require it as part of the destruction process but crushing and/or shredding is recommended. By degaussing HDDs, companies are choosing the most secure method of data sanitization per NSA guidelines as this is the only way companies can be certain that their data has been properly destroyed. When magnetic media is degaussed, the machines use powerful magnetic fields to sanitize the magnetic tapes and drive, wiping all sensitive information from the device. This act renders the drive completely inoperable, which should always be the goal.

Once the device has been degaussed, it should be physically destroyed. The combination of degaussing and physical destruction for HDDs is without a doubt the most secure method of ensuring your end-of-life data stays at the end of its life. Not even the most skilled of hackers will be able to get any information off of the drive, simply because there’s nothing left on it to hack!

Regardless of the catalyst for end-of-life drive destruction, it is always best practice to conduct destruction and degaussing in-house. It is also important to remember that a data breach is a data breach, no matter the level of impact. Blancco writes that, “not all degaussing machines are adequate to the task of demagnetizing all HDDs.” They’re right.

At SEM we have an array of various high-quality NSA listed/CUI and unclassified magnetic media degaussers, IT crushers, and enterprise IT shredders to meet any regulation. Any one of our exceptional sales team members are more than happy to help answer any questions you may have and help determine which machine will best meet your company or federally regulated destruction needs.

Think Your End-of-Life Data is Destroyed? Think Again!

August 25, 2020 at 9:00 am by Amanda Canale

When it comes to our personal data, some companies will go above and beyond to obtain it. Unfortunately, some companies don’t always take the same time and care when it comes to the destruction of that data. Recently, Morgan Stanley has come under fire for the possible data breach of their clients’ information. On July 10, the financial institution issued a statement to their clients that there were, “potential data security incidents” related to their personal information.

The incidents, which have occurred over a span of four years, were caused by an ITAD (IT asset disposition) vendor misplacing a number of various computer equipment that were being used to store customers’ personally identifiable information (PII).

data-privacy-day

A company like Morgan Stanley risks data security breaches every step of the way when opting for a third-party route; this can not only cause irreparable damage to their clients but to their brand as well. The belief that recycling hard disk drives (HDDs) and solid state drives (SSDs) is best practice, can, unfortunately, lead to major consequences.

While there are some reputable data sanitization companies in existence, if a company chooses to utilize an ITAD vendor instead of conducting end-of-life destruction in-house, the number of safety risks can be immeasurable. It can be far too easy for an ITAD vendor to mishandle or misuse drives when in transportation, being sorted by staff, and in the actual acts of destruction and disposal. Some contracted salvage vendors have even been known to sell the equipment they are given to online third parties.

It is a scary but common misbelief that simply erasing drives clean is enough to keep your information safe. When erasing data off of a drive, it’s possible that unencrypted and encrypted information can linger and be easily accessible by hackers. Morgan Stanley chief information security officer, Gerard Brady, wrote, “The manufacturer subsequently informed us of a software flaw that could have resulted in small amounts of previously deleted data remaining on the disks in unencrypted form.”

While Morgan Stanley has issued a statement promising that they will pay for two years of credit monitoring for their customers whose data may have been breached, it frankly isn’t enough for some clients as this possible breach may not affect them until much later.

“There is no statute of limitations on future data breaches,” writes Bob Johnson of the National Association for Information Destruction (NAID). “If a hard drive turns up five or 10 years down the road with personal information on it, it is still a data breach plain and simple. Ignoring missing or improperly wiped electronic media today simply means there are a bunch of time bombs floating around.”

It is this particular reason why we at SEM stress that all hard disk drives be degaussed and destroyed and done so in-house. When destroying data in-house, companies can be positive that the data is successfully destroyed whereas when given over to a vendor, the company forfeits any and all oversight. SEM degaussers use powerful magnetic fields to sanitize the magnetic storage media which renders the drive completely inoperable. No matter what the industry, purchasing in-house, end-of-life data destruction equipment is well worth the investment simply because it is impossible to be certain that all data has been destroyed otherwise. This can in turn potentially save the company more time and money in the long run by preventing breach early on.

While Morgan Stanley was unaware of the dangers that come with hiring third party data sanitization companies, they, along with their clients, are unfortunately the ones who are left to suffer the consequences of the vendor’s negligence.

At SEM we have an array of various high-quality NSA listed/CUI and unclassified magnetic media degaussers, IT crushers, and enterprise IT shredders to meet any regulation. Any one of our exceptional sales team members are more than happy to help answer any questions you may have and help determine which machine will best meet your personal or regulated destruction needs.

(To read more about how one’s trash can easily become another’s treasure, read one of our previous blog posts here.)

How to Destroy Tipping Foil, RFID and EMV Chips, and Magnetic Stripes in Credit Cards

June 16, 2020 at 10:00 am by Flora Knolton

Tipping foil is used to enhance and secure financial institutions’ cards. The metallic ribbon is fixed on the card’s embossed characters, helping to bring out the embossed characters even more. This results in clearer alphanumeric characters that are easier to read. This ribbon also improves bank card durability, as it’s designed to resist daily wear and tear and to maintain plastic card quality over the years. They are like the “makeup” for the face of the card. Tipping foil is essentially stamped onto the raised lettering during the in-line vertical personalization process. What is important to remember is that the embossed, foiled letters are now reversed on the sheet of foil they were stamped from, much like a typewriter ribbon. The physical impression left behind on the foil is why it is so critical that tipping foil needs to be destroyed prior to throwing away.

However, this method of creating credit/debit cards is currently being phased out. Many years ago, numbers had to be raised and embossed on the front of the card so when it was run through a card reader, an imprinted image of those numbers would appear on a slip of paper for the customers to sign. But traditional magnetic stripes are well on their way out as “microchip” card readers are becoming the new way to pay. Magnetic stripes on cards contain all of the cardholder information needed to make a purchase or duplicate the card. As technology advances, so do the world’s best hackers, and the magnetic stripe is significantly becoming easier for people to steal data from.

The EMV® (Europay, Mastercard, and Visa, after the three credit card networks that originally developed the protocol) credit and debit cards equipped with computer chips are now the global standard used to authenticate transactions. The data stored in a magnetic stripe is stagnant — it is how it is, and always stays the same. On the contrary, the chip in the card generates a unique code for each transaction and is only used once. If a thief were to copy the chip’s information to validate during a transaction, they wouldn’t be able to. No two transaction codes are ever repeated, so each code becomes useless following the completion of the transaction it represents.

The difference between contactless (RFID) transactions and chip transactions is the method by which the data is transferred. Radio frequency-enabled cards require the card to be within a short proximity of the payment terminal, rather than inserting the card into a cheap reader. EMV chip cards and contactless cards are both more secure than the magnetic stripe. Although, cards equipped with chips do not equate to fraudulent immunity by any means. NFC (Near Field Communication) skimming is where EMV-enabled cards can still be subjected to information being stolen. Near field communication skimmers utilize a wireless technology that allows data to transfer from a mobile device to a card reader within a short distance.

Consumers and organizations alike must properly shred their expired or useless cards that contain PII, whether that be in form of an EMV chip or residual printed tipping foil that still withholds information. Luckily, companies like SEM offer a host of devices specifically designed to ensure everyone has the opportunity to securely take control of their personal data and destroy it once and for all.

The Model DS-400 is one of our top multipurpose turnkey disintegrators. This powerhouse high security model was evaluated by the NSA, listed on the NSA/CSS EPL, and specifically designed to destroy metal cards and license plates. This device can also securely destroy classified paper and CDs as well as other unclassified media stored on smaller forms of e-media such as flash and thumb drives, solid state drives (SSDs), and SIM chips.

The Model 0205NANO is just one part of a revolutionary SSD destroyer duo. The NANO is a mobile crushing solution that was solely designed for the destruction of the world’s smallest forms solid state media. From Compact Flash Type 1 drives to SOIC-8 and SD cards to PLCC-32 drives, the 0205NANO crushes the SSD beyond recovery by the specially crafted and designed internal rotors.

The second solution in the 0205 SSD duo is the Model 0205MICRO. Like the NANO, the MICRO was specifically designed to destroy a wide variety of other SSD media such as, cell phones, PC boards, IronKeys, small tablets, and more.

The key to understanding how to destroy something properly is by first having an understanding of how said technology works. A number of our disintegrators would also do the job for destroying tipping foil, EMV chips, SSDs, and various media, at a number of different volumes. We also have devices that can easily destroy tough metal credit cards.

Classified or unclassified, there’s a way to destroy it. Leaving data in a stockpiled room “unsure of what to do” with it is not excusable, and yet many still haven’t educated themselves further to see how their negligence is putting their lives and companies at risk. Mitigate those risks today and be smart when handling personally identifiable information (PII) with Security Engineered Machinery. We’re always eager to help answer questions and can assure you we will help you meet your destruction requirements.

The Effects of Compromised Personally Identifiable Information

November 12, 2019 at 2:42 pm by Paul Falcone

Today more than ever, data security is a hot-button topic, with serious data theft and data breaches seemingly occurring on a daily basis. Since storing sensitive personally identifiable information (PII) is now the norm for virtually all businesses, it is incumbent on those businesses to consistently ensure the integrity of that information.

Around the world, consumers are justifiably growing more concerned about data privacy. The European Union and countries such as Canada and the United States work to protect their individual and corporate citizens by enacting and enforcing regulations that restrict the use and flow of PII, as well as mandate how PII is stored, disseminated, and destroyed.

gdpr-data-center

Although organizations subject to PII regulations incur steep fines for noncompliance, the consequences can be significantly more severe for the individuals whose PII is breached. For example, compromised data can be exposed to manipulation and illegal transactions that ultimately lead to wholesale identity theft. In 2017 alone, identity thieves pilfered $16.8 billion from 6.64% of U.S. consumers, or approximately one of every fifteen people.

Within an organization, it is critical that your data storage and data end-of-life destruction processes are invariably sound and thorough and executed error-free. As the following real-life examples demonstrate, any instances of irresponsibility or lapses in oversight—such as discarding paper without proper shredding or disposing of still-readable hard drives—can have dire consequences, particularly to individuals’ livelihoods and reputations.

2017: Medical Records in Public Trash Bins in Hawaii

An anonymous resident of Palolo, Honolulu, found a stack of approximately 50 residents’ personal and medical information while using a public-access trash bin. Evidently, a local therapy center discarded the paperwork without taking the necessary security measures. The documents contained a “fraudster’s treasure trove,” including complete social security numbers, pictures of driver’s licenses and extensive medical information. Thankfully, the documents fell into the right hands; otherwise, lives could well have been ruined.

2019: Used Electronic Storage Devices Contained PII

Companies relying on a data removal plan rather than a data end-of-life destruction plan should reconsider their strategy. A recent study conducted by Blannco analyzed 159 used storage drives purchased from eBay. The data removal company discovered that an astounding 42% of the drives (66) still contained data. More disturbingly, more than fifteen percent of the drives (25) still contained PII. Furthermore, one of those drives came from a software developer that had been granted government security clearance.

In another recent study, a Rapid7 researcher procured 85 discarded hardware components from businesses, including old computers, flash drives, phones, and hard drives. Of the 85 devices, only two had been properly wiped and only three were encrypted. In total, the researcher collected 611 email addresses, 50 birth dates, 41 social security numbers, 19 credit card numbers, six driver’s license numbers, and two passport numbers.

data-theft

2010: Australians Have Identities Stolen by Hit Squad

Imagine being six-months pregnant, living in Israel, and yet somehow being wanted for murder in Australia. In fact, it’s a real-life nightmare for a former Melbourne resident. In 2010, she was one of three Australian citizens living in Israel who had their identities stolen and used by members of the Mossad hit squad while carrying out an assassination. In each case, the three individuals’ PII was swiped and used to forge passports in their names with the perpetrators’ photos. It has never been definitively determined how their PII was compromised.

2016: Albuquerque Man Arrested for Fraud—When He Himself Was the Victim

In 2016, a dispatcher for the Kirtland Air Force Base Fire Department and military veteran with a security clearance and no prior arrests was pulled over, detained, and booked in Las Vegas, New Mexico, on an outstanding fraud and forgery warrant. Subsequently, it was determined that a younger man had obtained the individual’s personal information in the fall of 2015. This younger man used the stolen ID to cash a check and was seen on camera. Despite marked differences in the two men’s physical appearances, the Albuquerque Police still issued a warrant for the dispatcher, resulting in a highly traumatic experience (which, by the way, led him to file a suit against local law enforcement).

2019: Woman Arrested After Identity Thief Steals Car Using Her Name

A 25-year-old Indiana woman was recently arrested and booked on charges of auto theft when an impersonator used her driver’s license to test drive and steal multiple vehicles. The woman did not know she was being investigated until she was detained two weeks after an incident. While she believes the identity theft was likely the result of a stolen purse, the exact circumstances are unknown since no arrests have been made.

identity-theft

Although it’s often impossible to know whether compromised data is the result of inadequate end-of-life procedures, faulty storage protocols, illicit cyber activity, or everyday petty theft, an overriding theme emerges from the above examples: given the extreme sensitivity of PII—and the dire consequences for individuals when PII is compromised—it is the legal and ethical responsibility of all businesses possessing PII to protect it. The onus is on them to ensure all reasonable measures and precautions are taken to ensure its absolute security and integrity, and, ultimately, its utter, irreversible destruction at end-of-life.

Companies like SEM provide state-of-the-art data end-of-life solutions that ensure PII is destroyed to the point of non-recovery, thereby mitigating the attendant risks of data theft and compromises for both individual and corporate citizens alike.

Personally Identifiable Information (PII): What It Is and Why It Must Be Destroyed

July 9, 2019 at 5:30 pm by Paul Falcone

We’ve all heard of ‘Personally Identifiable Information’ (PII)—those pieces of information about ourselves that are unique to us, and therefore make us identifiable and distinguishable from others. Well-known PII includes data such as full name, social security number, driver’s license number, passport information, medical records, and financial account numbers.

Yet, there are other types of PII that we, as individuals and consumers, put out there about ourselves which we do not consider to be personally identifying. These pieces of information include email addresses and social media usernames, phone numbers, mailing addresses, and even religion. Then there’s quasi-identifiers that are also available in public sources like your race, zip code, gender and birth date, that when used with other relevant data can easily identify you, too.

PII

Moreover, we often underestimate the power of some of our PII when, in fact, this information provides access to many facets of everyday life including our ability to drive, receive health care, and make large purchases (like buying a home).

Sensitive & Non-Sensitive PII: The Difference

Personally identifiable information falls within one of two groups: sensitive and non-sensitive. While many experts tout that sensitive data is what should be protected and encrypted, non-sensitive data is just as important to safeguard against unauthorized access and theft.

The following, although by no means exhaustive, are lists of most of these types of data:

Sensitive PII:

• Full name
• Social Security Number (SSN)
• Driver’s license
• Passport information
• Passwords and PIN numbers
• Biometric information (e.g. fingerprints, iris and retina scan, DNA, facial recognition)
• Medical records (e.g. PHI, all data under HIPAA regulations)
• Financial information (e.g. bank accounts and loans, credit and debit card numbers)
• Employee personnel records and tax information (includes Employer Identification Number)
• Digital/Electronic account information (e.g. email addresses, internet account numbers, digital account passwords)
• School identification numbers and records
• Private phone numbers (especially cell phone numbers)
• Mailing and/or home address

Non-Sensitive PII:

• Zip code
• Race
• Gender
• Date of birth
• Place of birth
• Religion
• Ethnicity
• Sexual orientation
• IP addresses
• Cookies stored on a web browser
• Outside-of-home addresses (e.g. workplace)
• Business phone numbers and public personal phone numbers
• Employment-related information (e.g. job title and status)

The Pervasiveness of PII

Too many individuals overlook the sensitivity of their personal information, or don’t realize how they are interconnected and how easily they can be pieced together to form a unique identity. What’s more, people often use unprotected means to share their personal information with family and friends, such as through text and SMS message, email, social media, and other messenger apps.

Many people even allow their personal, sensitive data to be saved on their computers and other electronic devices and drives so as to provide convenience when accessing digital accounts and places where information is stored. A survey conducted by Experian reported that the average person stores three to four pieces of sensitive information online, and 25% of Americans share credit card and PIN numbers with family and friends.

The Importance of Proper Data and Drive Destruction

PII holds immense value to identify thieves who want to use your information for their personal gain. Criminals (including cybercriminals) therefore also find value in stealing this information, either for the use of financial gain through sale to an identity thief or for ransom payment directly from the victim. This is why it is imperative that you not only make sure all of your sensitive data and PII is secure and protected, but that the data is rendered unreadable and unable to be reconstructed from the drive, device, or material that it’s stored on when it’s no longer needed. Moreover, this end-of-life destruction needs to extend to the drive, device, and/or material on which the data is stored.

Landfills and trash and recycling centers are easy targets for someone to rummage through and find a device or material that potentially contains PII and that can be restored. For instance, it’s not enough to clear data from a laptop hard drive. To ensure the total destruction of sensitive data to the point that it cannot be reconstructed, both data and device must be destroyed by overwriting non-sensitive information with software or hardware to clear the data, and by degaussing the media and rendering the magnetic field permanently unusable or destroying the media by shredding, melting, pulverization, disintegration, or incineration.

The Top 5 Ways Our Personal Data Gets Compromised

April 30, 2019 at 8:26 pm by Heidi White

It seems like we can’t go a week without hearing about a data breach or a situation in which personal data has been compromised. Unfortunately, cybercriminals are becoming more sophisticated in their antics and there is very little we can do to stop cyber attacks from happening.

We can, however, arm ourselves against hackers and identity thieves by first understanding the main ways in which our personal data can be compromised. Then, we can take necessary steps to safeguard our personal data and prevent criminals from accessing our private information.

Understanding How our Personal Data Gets Compromised

The fact of the matter is that there are many ways in which our personal data can become compromised. Yet, they all seem to boil down to five main reasons, some of which are under our control and some are not. 

The Top 5 Ways Personal Data is Compromised:

data-breach

1. Organizational Data Breach: In order to do business with us, organizations often require our personal information. From financial institutions and credit bureaus to medical groups, email and social media platforms, subscription-based platforms and data-storage cloud companies…the list goes on. We trust that the organization follows its outlined security protocols to keep our private information, private. When that organization fails to deliver on its security measures, as we’ve collectively witnessed with the recent onslaught of big-data and cloud-system security breaches, our personal information is subject to unauthorized access and theft. Be sure you trust the organization and understand its data management policies and procedures for how your personal data will be used, stored, secured and destroyed before sharing personal information.

2. Unsecured Internet Connection: Even though it’s enticing to stop in to your local coffee shop or public library to work remotely from your laptop or portable device, you should always check the security of the internet connection you’re about to use, first. Public or otherwise unsecured connections are the most susceptible to cyber-criminal activity; using an unsecured internet connection is like inviting the hackers to your doorstep. In short, if the internet connection can be accessed without a password, don’t connect to it. 

3. Unsecured Device: The same can be said for any device you use to access the internet. From smartphones to laptops and tablets and now smart home devices like Amazon Echo and Google Home; these devices hold troves of our personal and private data. Maintaining updated security software, firewalls and installing extra security like a two-way authenticator are imperative to ensuring your device is protected from outside penetration. Password strength also falls under device security. Passwords should never be the same, should include characters and numbers as well as letters and should never be something easily guessed about yourself. Even if you are using a secured internet connection, the lack of security or lack of updated security for your device is just another invitation for having your data stolen. 

4. Responding to a Scam: Scams are designed to look, read and feel as authentic a communication as possible. Email phishing, ‘robo’ calls and social engineering tactics like personality quizzes are just a few examples of the ever-growing scams hackers and cyber criminals have developed to steal your personal data—right from the horse’s mouth. We often (mistakenly) place our trust blindly into communication efforts like email, phone and social media because those are places we communicate with people and brands we do trust. Always be vigilant of the type of organization and the way in which they communicate with you before you answer. (The IRS, for instance, will never email you or call you for personal information.)

5. Data Storage and Disposal at Home: Probably one of the most overlooked ways in which our personal data can be compromised is how we manage our data at home. Do you have a safe, secure, and designated location at home for all your personal and private documents? (You should.) And, what do you do with sensitive information that you no longer need, like an expired credit card or an old bank statement? If your answer is to cut it up and throw it out, you’re putting your personal data at risk. This also holds true of old devices you want to get rid of. Consider the personal information amassed on the hard drives of your old laptop, tablet, smartphone or other data-storing device. If you don’t properly destroy the hard drive, the data can still be reconstructed and accessed long after you’ve disposed of the device (say, if you turned it over to a buy-back program or, worse, threw it in the trash for a dumpster-diver to find).

hard-drive-destruction
Security-focused organizations use hard drive shredders to destroy drives at end-of-life

Proper Data Destruction and Disposal

While there’s little you can personally do to protect your information from a data breach at an organization, ensuring that the companies with whom you do business have a comprehensive data security and destruction policy is a good first step. There are also ways for you to better control your own data security. Taking steps like assessing your internet connections and device security and thinking before you respond to any digital or telephoned communication can greatly help you ensure your private data stays secure and remains uncompromised. 

When it comes to home security measures and data disposal, we recommend you maintain a specific and private place for anything that contains your personal information, and that you bring end-of-life devices to a local data destruction day, often held at universities in the spring. Of course, if you are in the area, you are always welcome to bring your device to SEM for physical destruction. As a final note, if your personal data has been compromised and you’ve become a victim of identity theft, you should report the identity theft incident to the Federal Trade Commission (FTC) online at IdentityTheft.gov or by phone at 1-877-438-4338.

Is Your Data Disposal Plan GDPR-Ready?

November 21, 2018 at 3:29 pm by Heidi White

gdpr-readyWith GDPR just around the corner, data security has been enjoying some much-needed time in the limelight. Never before has there been such a hyper-focus on the protection of sensitive data, particularly confidential and personally identifiable information (PII) such as healthcare records, personal data, financial information, and legal records. While data privacy conversations have more traditionally revolved around identify theft issues, the new GDPR regulation prioritizes the fiduciary responsibility of all sensitive and personal information.

Savvy organizations began planning and implementing their GDPR compliance programs months ago. Because of the numerous ways in which GDPR mandates data privacy across all storage media and within all facets of an organization, a comprehensive compliance program requires a well-researched, detailed approach with multi-departmental buy-in and execution.

healthcare-data-securityFor example, a healthcare provider possessing sensitive patient data in the form of medical records is obvious. What would not be so obvious would be the numerous other places where a patient’s PII may reside. The scheduling department keeps PII such as address and birthdate, the billing department has financial and insurance information, while the marketing department may possess email and browsing data for patient communications. And let’s not forget the backup servers. Personal data is literally everywhere.

Safeguarding sensitive data throughout an organization is critical, and many organizations are well aware of the need for firewalls, passwords, physical security measures, encryption, and employee training. What may be more of a need and challenge for some organizations is GDPR’s Article 17 Right to Erasure, also known as the “right to be forgotten.” While it is not an absolute, the basic premise of Article 17 is that an individual’s request to have his data removed must be honored within 30 days. In some instances, the request is not realistic. For example, banks must retain records for a minimum of seven years, so deleting the data would be in direct conflict to an existing legal mandate. However, Article 17 states that individuals have the right to have their personal data erased without undue delay if the data is no longer necessary for the purpose for which it was originally processed or collected, and this applies in a large number of cases with consumer transactions.

online-data-securityConsumer transactions typically include the storage of personal information such as address, phone, and payment information. While large organizations may have their own servers and storage solutions and are therefore more easily able to purge a consumer’s data from their system, the thousands of smaller organizations typically rely on outside vendors and cloud storage providers to manage their data. Data stored in the cloud is actually housed in data centers, where data is duplicated across multiple drives in an effort to create redundancies that help to mitigate data loss when drives fail — and drives DO fail on a very regular basis. After all, these drives are running 24 hours a day, seven days a week, year-round, so their life expectancy is understandably rather short. When a drive fails, the data it contains is still for the most part intact. Therefore, a comprehensive data disposition program should always include drive destruction so that personal data is not compromised at end-of-life. But end-of-life is only part of the problem. Smaller organizations and others who outsource their data storage must confirm with their providers that their data removal policy is GDPR compliant and must include policies and procedures for the Right to Erasure in their GDPR programs.

GDPR is a broad and encompassing regulation that is actually long overdue. While implementing a GDPR program is proving to be more challenging than organizations may have originally thought, particularly with regard to Article 17 and the Right to Erasure, the safeguarding of data and the diligent focus on data privacy have been positive results of GDPR. In a time where data breaches and identity theft are increasing exponentially, the implementation of a means by which to protect our privacy and security is most welcome.